ssm.ro Docs
Legal, SLA & SupportLegal Policies

Privacy Policy

Processing of personal data through the SSM.ro platform — categories, purposes, rights, and security

Data Controller

CONSULTIA S.R.L. and CONSULTIA DIGITAL S.R.L. (joint controllers under Art. 26 GDPR), headquartered in Brașov, str. Pârâului nr. 7, Brașov county, acting as joint personal data controllers, inform you about the processing of your personal data through the SSM.ro platform in accordance with Regulation (EU) 2016/679 (GDPR) and applicable national legislation.

Last updated: 28.10.2023


What Personal Data We Process

CategoryExamples
Personal and contact dataFirst and last name, job title, qualification, education, address, mobile phone number, email address
National identification numberCNP, ID card/passport series and number — required only exceptionally, for issuing a qualified electronic signature certificate
Billing dataBilling address, company name and tax ID (CUI), bank account (for issuing invoices and collecting payment by transfer)
Professional detailsEmployer, position, employee badge number, ID card number
Opinions and viewsFeedback submitted directly or posted publicly on social networks
Online identification dataIP address, operating system, browser, pages accessed, access date, number of authorizations

Source of Personal Data

The data is collected:

  • Directly from the data subject — by filling in contact or order forms, when preparing an offer, or when concluding the contract
  • Through an intermediary — when you access a partner application that transmits data for a quote request
  • From your employer — in order to establish the business relationship and grant access to the platform

PurposeGDPR Legal Basis
Access and use of the SSM.ro platform (account registration, training, courses)Art. 6(1)(b) — performance of a contract
Advanced electronic signature (standard flow — only the document hash is processed)Art. 6(1)(b) — performance of a contract
Qualified signature certificate (exceptional — signatory identification: CNP, ID document series/number, ID copy)Art. 6(1)(c) — legal obligation; Art. 6(1)(b) — performance of the contract with the signature provider
Communication (email, SMS — notifications, OTP, platform access)Art. 6(1)(b) — performance of a contract
Marketing (newsletter, service updates — only with consent)Art. 6(1)(a) — consent
Legal obligations (archiving, accounting, security, records)Art. 6(1)(c) — legal obligation
Financial management (invoices, payments, debt recovery, reports)Art. 6(1)(c) and (f) — legal obligation / legitimate interest
Dispute resolution (formulating requests before authorities)Art. 6(1)(f) — legitimate interest
Customer care (surveys, service audits, complaint resolution)Art. 6(1)(f) — legitimate interest

Who We Disclose Data To

As a rule, data is not disclosed to other companies, organizations, or persons. Identified categories of recipients:

  • Your employer — under the contract between SSM.ro and the employer, when you are the beneficiary of the services
  • Public authorities — ITM (Labor Inspectorate), Police, structures of the Public Ministry, in accordance with applicable legislation
  • Service providers (joint controllers) — for example, the electronic signature provider receives the data necessary to identify the signatory
  • State institutions, auditors, lawyers, consultants — legally or contractually bound to confidentiality
  • Processors — IT service providers, payment providers, archiving providers; bound to comply with GDPR requirements through a written agreement
  • Contractual partners — marketing, SEO, and design service providers, under processing agreements

Transfers to Third Countries

As a rule, personal data is processed within the European Economic Area (EEA). We do not use Google Analytics or other analytics/marketing cookies that transfer personal data outside the EEA. Traffic analysis on the presentation website is done using Plausible (cookieless, hosted in the EU, no personal data), and the SaaS platform does not include any web analytics tool.

The only possible transfers outside the EEA come from certain technical monitoring providers (New Relic, Sentry), which generally receive only error/performance traces and the associated account identifier — without user content or personal data. These transfers are covered by standard contractual clauses (SCC). Details: International Data Transfers.


How Long We Store Data

  • Data is stored in accordance with the legislation applicable to each processing purpose, limited to what is strictly and legally necessary
  • Data processed based on consent is irreversibly deleted immediately after consent is withdrawn (Art. 7(3) GDPR)
  • Data that has become unnecessary or has reached its retention deadline is irreversibly deleted/destroyed from all databases and storage media
  • By exception, data may be stored for longer periods if necessary to defend a right in court

Data Security

Technical and organizational measures implemented:

MeasureDescription
Dedicated policiesProcessing policies and practices reviewed periodically; physical and electronic security measures
Data minimizationWe process only the data that is necessary, adequate, and relevant to the stated purposes
Access restrictionAccess to data strictly limited to employees and collaborators who need it; confidentiality obligations
Data accuracyPeriodic requests to confirm the accuracy of processed data
Staff trainingOngoing training and testing on GDPR legislation and best practices
Anonymization/pseudonymizationWhere possible and appropriate, data is anonymized/pseudonymized
Vendor controlContractual clauses to ensure data protection with processors and joint controllers

Your Rights

RightDescription
Right to be informedThis policy provides the information you are entitled to
Right of accessConfirmation that data is being processed and access to details about how it is managed; response within 1 month
Right to rectificationCorrection of inaccurate data; response within 1 month; changes are also communicated to relevant third parties
Right to erasureDeletion of data in situations provided for by GDPR (unnecessary data, withdrawal of consent, etc.)
Right to restriction of processingHalting processing while retaining the data, under the conditions provided by law
Right to data portabilityProviding data in a portable format, to the extent technically possible
Right to objectHalting processing based on legitimate interest or for direct marketing purposes
Right not to be subject to automated decision-makingSSM.ro does not make decisions based exclusively on automated processing, except for processes necessary for the performance of the contract

Consequences of Not Providing Data

There is no general obligation to provide personal data. However:

  • Without basic data (name, email) — it is not possible to provide the requested services
  • Without a phone number — the OTP code for the electronic signature will be communicated by email (not by SMS)
  • Without a national identification number (CNP) and a copy of the ID document — a qualified electronic signature certificate cannot be issued (legal obligation to identify the signatory); the standard advanced electronic signature remains available

Contact and Exercising Your Rights

To exercise your rights or for further information regarding data processing:

  • Email (personal data / GDPR): dpo@ssm.ro
  • Address: CONSULTIA S.R.L. / CONSULTIA DIGITAL S.R.L., Brașov, str. Pârâului nr. 7, Brașov county
  • Data Protection Officer (DPO): Neoprivacy SRL — marius.dumitrescu@neoprivacy.ro

You also have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP): www.dataprotection.ro


Changes to This Policy

The controllers may amend this policy periodically. We will inform you in advance and will not reduce your rights through any changes made. Previous versions are archived and can be made available upon request.